Skip to main content
WP HealthKit
62 verification layers58 deterministic scanners4 AI engines

Audit any WordPress plugin or theme — in minutes.

Upload a ZIP or paste a wp.org slug. 58 deterministic scanners and 4 AI engines check security, quality, PHP & WordPress compatibility, and accessibility — then deliver a grade, a Fix Plan, and compliance docs (CRA, GDPR, WCAG/EAA) agencies can white-label for every client site.

Unlimited scans · 1 free AI audit · No card required

Now scanningharbor-and-oak.com
HarborStripe@3.4.1ZIP · 1.8 MB
  • Unpacking ZIP
  • Wordfence CVE DB
  • Secret scanner (22)
  • PHP 8.0–8.4 compat
  • PHPCS WordPress
  • REST auth scanner
  • GDPR scanner
  • AI security engine
  • AI accessibility
Audits completed
—
live count
Findings flagged
—
across all audits
Plugins graded
—
distinct wp.org plugins
Verification layers
0
58 deterministic + 4 AI
Audit data sourced fromWordfence IntelligenceWPScanOSV.devPackagist AdvisoriesPHPCSPHPStan L5WCAG 2.1 AAEU CRAWCAG 2.2Dynamic REST probeSARIF

62 verification layers

58 deterministic scanners. 4 AI engines. Zero guesswork.

We verify known facts first — CVEs, secrets, dependency advisories, REST authorization, GDPR, compatibility — before any AI looks at your code.

Deterministic scanners

58 · verifiable facts only

Every finding is cross-checked against a source of truth. If a scanner can't prove it, it doesn't report it.

Wordfence CVE DB412k records
WPScan + WPVulnerabilityadvisory feeds
Composer advisoriescomposer.json
npm / JS depsOSV.dev batch
Secret scanner22 patterns
PHP 8.0–8.4 compatdeprecations
PHPCS WordPresscoding standard
PHPStan level 5type safety
Semgrep + Psalmstatic analysis
REST API authorizationpermission_callback
GDPR scannerconsent + erasure
Gutenberg blocksrender_callback
Host compatibilityWPE / Kinsta / Flywheel
CRA complianceSECURITY.md / VDP
Multisite compatnetwork options
GPL / licenseComposer + npm
CodeCanyon / Envatosubmission rules
Theme scannerFSE / customizer
Hook wiring auditactions/filters
Performance patternsN+1, caching
i18n readinesstranslatable
Database schemamigrations
Malware scannersignature db
Plugin conflictsknown pairs
WooCommerce compatHPOS / blocks
WP version compat5.0–7.0
Dynamic REST auth probewe attack it live
AI agent securityprompt injection
WCAG 2.2EAA mandatory
Update channel safetysupply chain
Phone-home detectortelemetry
Uninstall verifierdata cleanup
ENGINE / 01

Security engine

7 dimensions, AI-code-safety included.

Authn / AuthzREST gapsCSRF / XSS / SQLiAI code patterns
ENGINE / 02

Quality-of-Life engine

9 dimensions of production readiness.

Error handlingSettings UXi18nUpdate hygiene
ENGINE / 03

Accessibility engine

WCAG 2.1 AA + EAA · WCAG 2.2 deterministic.

Semantics · ARIAWCAG 2.2 SC 2.5.8 / 3.3.8Color · contrast
ENGINE / 04

Theme engine

Activates automatically for theme ZIPs.

FSE / block themesCustomizerAsset security

Only on WP HealthKit

Proof, not patterns.

Every scanner on the market pattern-matches your code and guesses. We go further: live sandbox attacks, cross-validated AI, and verdicts you can act on.

Living Audits · Powered by Reverify

Your audit was true on Tuesday. Is it still true today?

A security audit is a snapshot — but the facts it rests on keep moving. Living Audits re-verifies your report's claims of safety and currency against ground truth, forever.

LIVING / 01Findings born with a whyEvery CRITICAL and HIGH finding carries a structured rationale: the evidence that grounds it, why it earned its severity, what was assumed, and what would change the assessment.
LIVING / 02Claims re-verified foreverYour minimum PHP, tested-up-to WordPress, and every pinned dependency are re-checked against OSV, endoflife.date, wp.org, and library docs on a decay-aware cadence.
LIVING / 03Challenges, never rewritesWhen a PHP version EOLs or a CVE lands in a library you bundle, a signed challenge with quoted evidence attaches to your report. The original audit is never edited.
How Living Audits works →

Report card

One grade for every buyer. Four grades for every reviewer.

Every audit produces an A–D letter across Security, Standards, Quality and Compatibility — plus an embeddable Submission Readiness badge.

HarborStripe@3.4.1
Submission-ready
96
/ 100 overall
Verified 4 minutes ago
Security
A · 96
Standards
A- · 91
Quality
B+ · 86
A11y
B · 82
wphealthkitA · 96submissionreadyCVEs0 / 412kembed · auto-updates

Ship with proof

embeddable badges
wphealthkitA · 96submissionreadyCVEs0 / 412k
<a href="https://wphealthkit.com/r/hs-341">
  <img src=".../badge/hs-341.svg"
       alt="Production-ready · Grade A" />
</a>

Live-updates on every re-audit — your wp.org listing never goes stale. Every grade links back to the public report it came from.

Free tools

Useful before you ever sign up.

All 5 tools →

Pricing · GBP

Audits that used to cost thousands. Your first AI audit is free.

Deterministic scans are unlimited on every plan — you only spend tokens when the AI engines read your code.

Free
£0forever

The most generous free tier in WordPress security.

  • Unlimited deterministic audits
  • 1 free AI audit · all 58 scanners
  • Report card (A–D) + directory listing
Start free
Most popular
Platform
£49/ month

For active plugin & theme authors.

  • 50 AI audits a month
  • Private results + signed receipts + SBOM
  • 3 sites monitored · GitHub Actions + CLI + API
Start 7-day free trial
Enterprise
£299/ month

Fleet dashboard, white-label, and BYOK for unlimited audits.

  • 300 AI audits/month · BYOK for unlimited
  • Fleet dashboard + 100 sites + 5 seats
  • CRA / GDPR / WCAG / EAA reports + white-label
Start free trial

Enterprise £299/mo with BYOK for unlimited audits · Platform £49/mo · Single audit £4.99 — full comparison →

Ship with the receipts. Not with your fingers crossed.

Your next audit is two minutes away — upload a ZIP, get a verifiable grade, and put the badge where your buyers can see it. Every audit mints a signed provenance receipt anyone can verify.

62 verification layers · 58 deterministic scanners + 4 AI engines · Results in ~2 minutes